12-21-2016 01:13 AM - edited 03-12-2019 01:41 AM
I think I know the answer to this, but questioning it as I am implementing something which is dependent on me being correct.
If a connection is established from Inside to Outside successfully, will that traffic be allowed back into the ASA due to it being an "established" connection and Ignore any ACL I might have on the Outside Interface (Inbound)? I think yes...
Solved! Go to Solution.
12-21-2016 01:22 AM
That's true. ASA being a stateful appliance, will allow reply traffic and there is no need for allowing that traffic on outside interface acl. So, acl will be bypassed for already established connection.
Only for traffic initiated from outside, we would need an acl on outside interface.
-
AJ
12-21-2016 01:22 AM
That's true. ASA being a stateful appliance, will allow reply traffic and there is no need for allowing that traffic on outside interface acl. So, acl will be bypassed for already established connection.
Only for traffic initiated from outside, we would need an acl on outside interface.
-
AJ
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide